Cyber & AI intelligence
Wasteland.
Briefs indexed2975
Issues30
Published Mondays07:30 CT
▣ Breach PENTAGON-DOD-PERSO 2026-10-02

Pentagon DMDC: File-Sharing Vulnerability Exposes Millions of Military Personnel Records

"The Defense Manpower Data Center (DMDC), the Pentagon's personnel-data agency, is sending breach notices to current and former military members, civilian staff and others. The notices say unauthorized users had access…"

The Defense Manpower Data Center (DMDC), the Pentagon's personnel-data agency, is sending breach notices to current and former military members, civilian staff and others. The notices say unauthorized users had access to unencrypted personal records for about nine months, from October 2025 until 16 July 2026. Defense officials have given CNN, MeriTalk and Federal News Network a count of 2.76 million living individuals and 294,000 deceased individuals, about 3.05 million records in total. Published figures vary. TechRadar's headline says 2.7 million. BleepingComputer and TechCrunch say "nearly" or "about" 2.8 million living people. Military Times cites two unnamed people who say about four million may be affected. The notification letter itself gives no count. Only the Department of Defense (which now also calls itself the Department of War) has confirmed the breach. The attacker has not been identified, and no group has claimed responsibility.

What Happened

Military Times and SecurityWeek report that the notification letter is dated 18 September 2026. Recipients have posted copies on Reddit, and Military Times says two defense officials confirmed the letter is authentic. Its main points:

About two months passed between discovery in mid-July and the 18 September letter. IDX (Identity Theft Guard Solutions), which DoD contracts for this work, is mailing the notices. Reporting differs slightly on what was breached. BleepingComputer's headline calls it the Pentagon's "human resources management system." The letter and most other outlets describe a file server reached through a file-sharing system. The letter's own wording is more specific and should be preferred.

What Was Taken

The letter says the exposed data "varied by individual." Each recipient's Social Security number was exposed together with at least one more identifier from this list:

The scale of the data store matters too. DMDC holds more than 60 million records (FY2024) covering service members, civilians, contractors, family members, retirees and veterans. TechCrunch notes that DMDC also calls itself the military's "leading identity management provider." It links people to the credentials, such as CAC smart cards, that grant access to Pentagon systems, buildings and bases. Based on the notices, the exposed data was personnel records, not credentials. The affected group also includes about 294,000 deceased people, whose identities are often used in benefits and identity fraud because nobody is watching their credit.

Why It Matters

The Attack Technique

Public detail is limited. What is known:

It is still unknown whether the flaw was a zero-day or a known CVE that went unpatched, which product was affected, and whether anything beyond file reads happened, such as lateral movement or persistence. Defenders should treat any reported link to a specific MFT product as speculation until DoD or a vendor advisory confirms it.

What Organizations Should Do

  1. Inventory and harden file-sharing and MFT systems. List every internet-facing file transfer and file-sharing appliance. Apply vendor patches quickly, and put administrative and upload interfaces behind VPN or zero-trust access where you can.
  2. Encrypt sensitive PII at rest and limit how long staging copies live. File shares should not hold plaintext SSN datasets. Use application- or file-level encryption, tokenize SSNs where possible, and delete bulk exports once the transfer is complete.
  3. Hunt for long-dwell access. Review at least 12 months of file-server and MFT logs for unusual source IPs, off-hours bulk downloads, new or dormant accounts, and web shells. This incident went unnoticed for about nine months.
  4. Monitor data egress. Set baselines for normal transfer volumes from systems that hold PII and alert on deviations. Feed MFT logs into the SIEM instead of leaving them on the appliance.
  5. Brief exposed staff on targeted social engineering. Defense contractors and agencies whose staff overlap with DMDC records should warn people about phishing, vishing and fake recruitment approaches that use personnel details. Affected individuals should enroll in the IDX monitoring on offer. BleepingComputer reports 12 months of coverage with an enrollment deadline of 19 August 2027. They should also consider a credit freeze.
  6. Protect records of deceased individuals. Organizations with deceased-person records in scope should check that death notifications have reached the credit bureaus and the SSA, so the identities are harder to reuse.

Sources: Massive Pentagon hack sees records of 2.7 million US military perso... | Hackers stole Pentagon personnel records of over 3 million people | Hackers stole millions of US military personnel records during mont... | Pentagon Personnel Agency Data Breach Impacts 3 Million ... | Three Million Affected in Pentagon Personnel Agency Data Breach - S... | Pentagon data breach of military personnel raises national security... | Military personnel data exposed in breach, agency warns | Pentagon Database Breach Exposes Personal Information of More Than...